One of our clients is migrating to GCP and is interested in a landing zone design that is SOC2 compliant. From this perspective anything i need to keep in mind for landing zone design? I totally understand that the GCP services by themselves are SOC2 compliant. It is only the landing zone that i want to understand, anything that needs to be taken care of from a SOC2 compliance audit down the line.